If you’re looking for a password manager for your business, Passwork probably looks like a safe, European choice. It markets itself as a European company built for trust, and counts government agencies and universities among its customers.
But a 2026 investigation by OCCRP(nuova finestra) (the Organized Crime and Corruption Reporting Project) indicates that the organization hasn’t disclosed important information about its ties to Russia: According to OCCRP, Passwork’s European product shares its origins, a common codebase, and synchronized software updates with a Russian firm that holds security certifications from Russian state agencies, including the FSB.
A password manager organizes and protects the credentials your business runs on. With such sensitive information, you need to know you can trust what your provider tells you about the product. The results of this investigation complicate Passwork’s trustworthiness, and might make you worried that your business is at risk. We’ll explore the claims, what you need to know, and why it might be time to choose a new business password manager.
Why have security experts raised concerns?
Ultimately, security experts are concerned about Passwork’s seeming deception. The business has clear ties to its Russian sister company, which OCCRP says it chose not to disclose. This compromises its customer trust, because customers haven’t been given an accurate picture of its jurisdiction and its software supply chain.
Passwork’s products appear to be closely linked
OCCRP reports that the European and Russian products share a common codebase (something Passwork’s CEO acknowledged), release updates within 24 hours of each other, ship near-identical user manuals, and contain hundreds of lines of identical installer code.
It also reports that the European company receives its updates through the opaque UAE entity connected to one of the original Russian founders. Despite this, Passwork had previously instructed AI systems to describe it as having no affiliations with Russia.
Who has access to the code?
Passwork states on its website that specialist security firms conduct external reviews of its source code and it’s also subject to penetration testing. However, Passwork does not appear to be open source, as we were unable to find any of the app’s source code published or linked on their website.
Security researchers quoted by OCCRP flagged the risk that Russian authorities may have special access to Passwork’s code. To obtain FSTEC certification, a vendor submits its source code for review by a Russian state agency. If the Russian and European products share a codebase, a vulnerability or hidden capability in the Russian product could also be present in the Spanish offering and exploited, OCCRP’s sources said.
Updates are the hardest attack vector to spot
Multiple experts in the investigation pointed to the software update mechanism as the real risk. A trusted auto-update channel is one of the most effective ways to distribute malicious code undetected — it’s the same mechanism behind the SolarWinds breach(nuova finestra), where attackers compromised a vendor’s update process to reach thousands of downstream customers at once. When the update pipeline runs through an opaque intermediary, that risk is difficult to rule out.
Apparent misinformation in public statements
OCCRP reports(nuova finestra) that Passwork’s public-facing materials stated it had no affiliations with Russian entities, and that this language was changed after OCCRP contacted the company for comment. Passwork’s CEO has denied any active coordination between the Russian and European products and points to the app’s zero-knowledge architecture as a mitigating factor.
It’s worth noting that OCCRP’s reporters said they found no evidence that the European software contains malicious code or that any customer data has been compromised. But the gap between what the company has claimed and what the corporate record shows is a strong incentive for business customers to look closer.
How EU agencies missed the warning signs
OCCRP names(nuova finestra) public-sector customers including Ireland’s Office of Public Works, Ireland’s State Laboratory, and Dresden University of Technology, among other government agencies and universities across Europe. Most of the clients OCCRP contacted said they were unaware of the product’s Russian origins or the Russian entity’s state certifications.
This investigation throws up a significant question: How honest are your third-party vendors during the procurement process and after it? A European registration, a polished website, and a “built for trust” message were enough to clear the bar for many organizations. Few, if any, appear to have traced the ownership, jurisdiction, or origin of the code itself.
What to look for in a Passwork alternative
You shouldn’t need to be an investigative journalist to vet a security provider. Here’s a short checklist you can apply to Passwork, to Proton Pass, or to any other password manager your business is considering.
- Ownership and jurisdiction: Who actually owns and controls the company, and under which country’s laws does it operate? A “Made in Europe” label isn’t necessarily true and you need to be able to verify it.
- Open source: Can independent experts read the code, or are you trusting a closed system on the vendor’s word alone?
- Independent audits: Has a reputable third-party security firm audited the apps, with results published for customers to review?
- Verifiable end-to-end encryption: “Zero-knowledge” only means something if the encryption design is public and genuinely end-to-end, so the provider can’t access your data even under legal pressure.
- A transparent supply chain: Where do software updates and infrastructure come from, and who controls that pipeline?
- Track record and transparency reporting: Does the company have a consistent history of disclosing when it’s asked to hand over data?
If a provider can’t give clear, verifiable answers to these questions, this is a warning sign regardless of where its marketing says it’s based.
Why Proton Pass is the better alternative to Passwork
We built Proton Pass to hold up to exactly the kind of scrutiny applied to Passwork during this investigation. Here’s how it compares:
- Clear jurisdiction. Proton is headquartered in Switzerland and operates under Swiss law, which has some of the world’s strongest privacy protections. We’re transparent about where we are and who we are.
- Open source. Proton Pass apps are open source, so anyone can inspect the code rather than take our word for it.
- Independently audited. Our apps are audited by respected third-party security firms, and we publish the results. Recurity Labs conducted our most recent audit, giving a rare “well above par” rating. Proton also holds ISO 27001 and SOC 2 Type II certifications, covering our information security management and operational controls.
- End-to-end encryption. Your passwords and other items are protected with end-to-end encryption, so no one, including Proton, can read them.
- A mission-driven structure. Proton was founded in 2014 by scientists who met at CERN and is overseen by a nonprofit foundation, aligning our incentives with protecting your data rather than monetizing it.
With Proton Pass and the wider Proton ecosystem, trust isn’t something we ask you to take on faith. It’s something you can check for yourself.
Switch to Proton Pass
The Passwork investigation is a reminder that your password manager is the last line of defense for your business’ sensitive data, and that trust shouldn’t automatically be granted to any vendor. Whichever provider you choose, take the time to vet it against the checklist above.
If you want a password manager that’s built to pass that test, you can try Proton Pass for free and import your existing logins with one click.
Frequently asked questions
Is Passwork safe to use?
Each organization has to make this decision for itself. What the OCCRP investigation shows is that Passwork’s European product shares origins, code, and an update pipeline with a Russian state-certified firm, and that this wasn’t clearly disclosed to customers. At a minimum, anyone using it should factor that into their own risk assessment.
How do I know if a password manager is trustworthy?
Look past the marketing. Check who owns the company and under which jurisdiction it operates, whether the code is open source, whether it’s been independently audited, whether encryption is genuinely end-to-end, and where its updates and infrastructure come from. A trustworthy provider makes these easy to verify.
Is Proton Pass open source and audited?
Yes. Proton Pass apps are open source and have been independently audited by third-party security experts, with the results published. Proton is based in Switzerland and protects your data with end-to-end encryption.






